VYPR

rpm package

suse/libqt5-qtbase&distro=SUSE Linux Enterprise Module for Desktop Applications 15 SP5

pkg:rpm/suse/libqt5-qtbase&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP5

Vulnerabilities (10)

  • CVE-2024-39936Jul 4, 2024
    affected < 5.15.8+kde185-150500.4.22.1fixed 5.15.8+kde185-150500.4.22.1

    An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant decisions about an established connection may execute too early, because the encrypted() signal has not

  • CVE-2023-45935MedMar 27, 2024
    affected < 5.15.8+kde185-150500.4.22.1fixed 5.15.8+kde185-150500.4.22.1

    Qt 6 through 6.6 was discovered to contain a NULL pointer dereference via the function QXcbConnection::initializeAllAtoms(). NOTE: this is disputed because it is not expected that an X application should continue to run when there is arbitrary anomalous behavior from the X server

  • CVE-2023-51714Dec 24, 2023
    affected < 5.15.8+kde185-150500.4.16.1fixed 5.15.8+kde185-150500.4.16.1

    An issue was discovered in the HTTP2 implementation in Qt before 5.15.17, 6.x before 6.2.11, 6.3.x through 6.5.x before 6.5.4, and 6.6.x before 6.6.2. network/access/http2/hpacktable.cpp has an incorrect HPack integer overflow check.

  • CVE-2023-37369Aug 20, 2023
    affected < 5.15.8+kde185-150500.4.13.1fixed 5.15.8+kde185-150500.4.13.1

    In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2, there can be an application crash in QXmlStreamReader via a crafted XML string that triggers a situation in which a prefix is greater than a length.

  • CVE-2023-38197Jul 13, 2023
    affected < 5.15.8+kde185-150500.4.8.1fixed 5.15.8+kde185-150500.4.8.1

    An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.

  • CVE-2023-34410Jun 5, 2023
    affected < 5.15.8+kde185-150500.4.8.1fixed 5.15.8+kde185-150500.4.8.1

    An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always consider whether the root of a chain is a configured CA certificate.

  • CVE-2023-32763May 28, 2023
    affected < 5.15.8+kde185-150500.4.3.1fixed 5.15.8+kde185-150500.4.3.1

    An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. When a SVG file with an image inside it is rendered, a QTextLayout buffer overflow can be triggered.

  • CVE-2023-32762May 28, 2023
    affected < 5.15.8+kde185-150500.4.8.1fixed 5.15.8+kde185-150500.4.8.1

    An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This

  • CVE-2023-33285May 22, 2023
    affected < 5.15.8+kde185-150500.4.8.1fixed 5.15.8+kde185-150500.4.8.1

    An issue was discovered in Qt 5.x before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. QDnsLookup has a buffer over-read via a crafted reply from a DNS server.

  • CVE-2023-24607Apr 15, 2023
    affected < 5.15.8+kde185-150500.4.8.1fixed 5.15.8+kde185-150500.4.8.1

    Qt before 6.4.3 allows a denial of service via a crafted string when the SQL ODBC driver plugin is used and the size of SQLTCHAR is 4. The affected versions are 5.x before 5.15.13, 6.x before 6.2.8, and 6.3.x before 6.4.3.